Cofense Report Details Campaigns That Exploit Trust in Browser Workflows

· Original article ↗

Summary

Cofense examines fake software-installation lures, Browser-in-the-Browser phishing, ClickFix, and device-code phishing, showing how attackers exploit trusted browser interactions to steal credentials or deliver malware without exploiting browser vulnerabilities.

Key points

  • The report describes a shift from exploiting browser software to manipulating users through familiar browser prompts and workflows.
  • Fake update, document-viewer, and app-store pages can trick users into installing information stealers or remote-access tools, including ConnectWise RAT and Action1 RAT.
  • Browser-in-the-Browser pages imitate login pop-ups to steal credentials; ClickFix prompts users to run commands under the guise of a browser check.
  • Since March 2026, Cofense observed growing use of device-code phishing, which gets victims to authenticate on Microsoft's legitimate site using an attacker-supplied code.
  • These techniques exploit user actions rather than browser vulnerabilities, making browser patching alone insufficient.
  • Cofense recommends monitoring, identity protection, behavioral analytics, and user education to help protect trusted browser interactions.

Article Details

Publisher
Cofense
Report Period
March–July 2026 for the device code phishing distribution; no overall reporting period stated.
Scope
Four browser trust abuse campaign types: software update and application installation lures, Browser-in-the-Browser, ClickFix, and device code phishing.
Key Statistics
  • The report examines four browser trust abuse campaign types.
Recommendations
  • Monitor trusted interactions within the browser.
  • Strengthen identity protection and behavioral analytics.
  • Educate users about deceptive browser prompts and authentication workflows.

MITRE ATT&CK

Vendors

Products

Related Articles